Writing

76 posts since 2020. Notes on blue teaming, detection engineering, SIEM/SOAR and incident response.

Featured

  1. 01MCP and SIEM Integration: Permission Surface Analysis on Splunk (Part 1)In this article we look at the MCP (Model Context Protocol) and Splunk integration from a security point of view. It covers the setup steps, the permission surface of the tools the server exposes and the precautions worth taking.14 min read
  2. 02Developing Sigma Rules1. What Is a Sigma Rule? A Sigma rule is an open-source language and rule-set format used to detect and investigate security events and threats.…13 min read
  3. 03What Is This Log4j RCE (Log4Shell)?In my new article, I'll be talking about a vulnerability that has been heavily discussed over the past few days. I hope it's useful. :) The vulnerability…10 min read

20261

20242

20236

202210

202138

202019